CVE-2012-3390: Low severity Moodle moodle vulnerability
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3390?
CVE-2012-3390 is classified as a medium severity vulnerability due to its potential for unauthorized information disclosure.
How do I fix CVE-2012-3390?
To fix CVE-2012-3390, you should upgrade Moodle to version 2.1.7 or 2.2.4 or later, where the vulnerability has been addressed.
Who is affected by CVE-2012-3390?
CVE-2012-3390 affects users of Moodle versions 2.1.0 through 2.1.6 and 2.2.0 through 2.2.3.
What type of attack can exploit CVE-2012-3390?
CVE-2012-3390 can be exploited by remote authenticated users to read sensitive files embedded in hidden blocks.
Is there a workaround for CVE-2012-3390?
There is no specific workaround for CVE-2012-3390; the best mitigation is to apply the recommended updates.